{"id":"https://openalex.org/W7118169019","doi":"https://doi.org/10.1109/tdsc.2025.3650683","title":"Decoder Gradient Shields: A Family of Provable and High-Fidelity Methods Against Gradient-Based Box-Free Watermark Removal","display_name":"Decoder Gradient Shields: A Family of Provable and High-Fidelity Methods Against Gradient-Based Box-Free Watermark Removal","publication_year":2026,"publication_date":"2026-01-05","ids":{"openalex":"https://openalex.org/W7118169019","doi":"https://doi.org/10.1109/tdsc.2025.3650683"},"language":"en","primary_location":{"id":"doi:10.1109/tdsc.2025.3650683","is_oa":false,"landing_page_url":"https://doi.org/10.1109/tdsc.2025.3650683","pdf_url":null,"source":{"id":"https://openalex.org/S133795288","display_name":"IEEE Transactions on Dependable and Secure Computing","issn_l":"1545-5971","issn":["1545-5971","1941-0018","2160-9209"],"is_oa":false,"is_in_doaj":false,"is_core":true,"host_organization":"https://openalex.org/P4310320439","host_organization_name":"IEEE Computer Society","host_organization_lineage":["https://openalex.org/P4310320439","https://openalex.org/P4310319808"],"host_organization_lineage_names":["IEEE Computer Society","Institute of Electrical and Electronics Engineers"],"type":"journal"},"license":null,"license_id":null,"version":"publishedVersion","is_accepted":true,"is_published":true,"raw_source_name":"IEEE Transactions on Dependable and Secure Computing","raw_type":"journal-article"},"type":"article","indexed_in":["crossref"],"open_access":{"is_oa":true,"oa_status":"green","oa_url":"https://hdl.handle.net/2031/70aed4c8-0cbc-449a-999c-8985268a4300","any_repository_has_fulltext":true},"authorships":[{"author_position":"first","author":{"id":"https://openalex.org/A5104279460","display_name":"Haonan An","orcid":"https://orcid.org/0009-0005-6874-0229"},"institutions":[{"id":"https://openalex.org/I168719708","display_name":"City University of Hong Kong","ror":"https://ror.org/03q8dnn23","country_code":"HK","type":"education","lineage":["https://openalex.org/I168719708"]}],"countries":["HK"],"is_corresponding":false,"raw_author_name":"Haonan An","raw_affiliation_strings":["Hong Kong JC STEM Lab of Smart City and Department of Computer Science, City University of Hong Kong, Hong Kong"],"raw_orcid":"https://orcid.org/0009-0005-6874-0229","affiliations":[{"raw_affiliation_string":"Hong Kong JC STEM Lab of Smart City and Department of Computer Science, City University of Hong Kong, Hong Kong","institution_ids":["https://openalex.org/I168719708"]}]},{"author_position":"middle","author":{"id":"https://openalex.org/A5121957889","display_name":"Guang Hua","orcid":null},"institutions":[{"id":"https://openalex.org/I168639165","display_name":"Singapore Institute of Technology","ror":"https://ror.org/01v2c2791","country_code":"SG","type":"education","lineage":["https://openalex.org/I168639165"]}],"countries":["SG"],"is_corresponding":false,"raw_author_name":"Guang Hua","raw_affiliation_strings":["Infocomm Technology Cluster, Singapore Institute of Technology, Singapore"],"raw_orcid":"https://orcid.org/0000-0001-5184-4359","affiliations":[{"raw_affiliation_string":"Infocomm Technology Cluster, Singapore Institute of Technology, Singapore","institution_ids":["https://openalex.org/I168639165"]}]},{"author_position":"middle","author":{"id":"https://openalex.org/A5121929956","display_name":"Wei Du","orcid":null},"institutions":[{"id":"https://openalex.org/I150229711","display_name":"University of Electronic Science and Technology of China","ror":"https://ror.org/04qr3zq92","country_code":"CN","type":"education","lineage":["https://openalex.org/I150229711"]}],"countries":["CN"],"is_corresponding":false,"raw_author_name":"Wei Du","raw_affiliation_strings":["School of Computer Science and Engineering, University of Electronic Science and Technology of China, Chengdu, China"],"raw_orcid":"https://orcid.org/0009-0007-5481-9379","affiliations":[{"raw_affiliation_string":"School of Computer Science and Engineering, University of Electronic Science and Technology of China, Chengdu, China","institution_ids":["https://openalex.org/I150229711"]}]},{"author_position":"middle","author":{"id":"https://openalex.org/A5013699453","display_name":"Hangcheng Cao","orcid":"https://orcid.org/0000-0002-0957-8576"},"institutions":[{"id":"https://openalex.org/I168719708","display_name":"City University of Hong Kong","ror":"https://ror.org/03q8dnn23","country_code":"HK","type":"education","lineage":["https://openalex.org/I168719708"]}],"countries":["HK"],"is_corresponding":false,"raw_author_name":"Hangcheng Cao","raw_affiliation_strings":["Hong Kong JC STEM Lab of Smart City and Department of Computer Science, City University of Hong Kong, Hong Kong"],"raw_orcid":"https://orcid.org/0000-0002-0957-8576","affiliations":[{"raw_affiliation_string":"Hong Kong JC STEM Lab of Smart City and Department of Computer Science, City University of Hong Kong, Hong Kong","institution_ids":["https://openalex.org/I168719708"]}]},{"author_position":"middle","author":{"id":"https://openalex.org/A5040546889","display_name":"Yihang Tao","orcid":"https://orcid.org/0000-0002-9596-4106"},"institutions":[{"id":"https://openalex.org/I168719708","display_name":"City University of Hong Kong","ror":"https://ror.org/03q8dnn23","country_code":"HK","type":"education","lineage":["https://openalex.org/I168719708"]}],"countries":["HK"],"is_corresponding":false,"raw_author_name":"Yihang Tao","raw_affiliation_strings":["Hong Kong JC STEM Lab of Smart City and Department of Computer Science, City University of Hong Kong, Hong Kong"],"raw_orcid":"https://orcid.org/0000-0002-9596-4106","affiliations":[{"raw_affiliation_string":"Hong Kong JC STEM Lab of Smart City and Department of Computer Science, City University of Hong Kong, Hong Kong","institution_ids":["https://openalex.org/I168719708"]}]},{"author_position":"middle","author":{"id":"https://openalex.org/A5046950426","display_name":"Guowen Xu","orcid":"https://orcid.org/0000-0002-9764-9345"},"institutions":[{"id":"https://openalex.org/I150229711","display_name":"University of Electronic Science and Technology of China","ror":"https://ror.org/04qr3zq92","country_code":"CN","type":"education","lineage":["https://openalex.org/I150229711"]}],"countries":["CN"],"is_corresponding":false,"raw_author_name":"Guowen Xu","raw_affiliation_strings":["School of Computer Science and Engineering, University of Electronic Science and Technology of China, Chengdu, China"],"raw_orcid":"https://orcid.org/0000-0002-9764-9345","affiliations":[{"raw_affiliation_string":"School of Computer Science and Engineering, University of Electronic Science and Technology of China, Chengdu, China","institution_ids":["https://openalex.org/I150229711"]}]},{"author_position":"middle","author":{"id":"https://openalex.org/A5097423664","display_name":"Prof Susanto Rahardja","orcid":null},"institutions":[{"id":"https://openalex.org/I76130692","display_name":"Zhejiang University","ror":"https://ror.org/00a2xv884","country_code":"CN","type":"education","lineage":["https://openalex.org/I76130692"]}],"countries":["CN"],"is_corresponding":false,"raw_author_name":"Susanto Rahardja","raw_affiliation_strings":["College of Information Science &#x0026; Electronic Engineering, Zhejiang University, Hangzhou, China"],"raw_orcid":"https://orcid.org/0000-0003-0831-6934","affiliations":[{"raw_affiliation_string":"College of Information Science &#x0026; Electronic Engineering, Zhejiang University, Hangzhou, China","institution_ids":["https://openalex.org/I76130692"]}]},{"author_position":"last","author":{"id":"https://openalex.org/A5016290340","display_name":"Yuguang Fang","orcid":"https://orcid.org/0000-0002-1079-3871"},"institutions":[{"id":"https://openalex.org/I168719708","display_name":"City University of Hong Kong","ror":"https://ror.org/03q8dnn23","country_code":"HK","type":"education","lineage":["https://openalex.org/I168719708"]}],"countries":["HK"],"is_corresponding":false,"raw_author_name":"Yuguang Fang","raw_affiliation_strings":["Hong Kong JC STEM Lab of Smart City and Department of Computer Science, City University of Hong Kong, Hong Kong"],"raw_orcid":"https://orcid.org/0000-0002-1079-3871","affiliations":[{"raw_affiliation_string":"Hong Kong JC STEM Lab of Smart City and Department of Computer Science, City University of Hong Kong, Hong Kong","institution_ids":["https://openalex.org/I168719708"]}]}],"institutions":[],"countries_distinct_count":3,"institutions_distinct_count":8,"corresponding_author_ids":[],"corresponding_institution_ids":[],"apc_list":null,"apc_paid":null,"fwci":0.0,"has_fulltext":false,"cited_by_count":0,"citation_normalized_percentile":{"value":0.02863371,"is_in_top_1_percent":false,"is_in_top_10_percent":false},"cited_by_percentile_year":null,"biblio":{"volume":"23","issue":"3","first_page":"5015","last_page":"5028"},"is_retracted":false,"is_paratext":false,"is_xpac":false,"primary_topic":{"id":"https://openalex.org/T11689","display_name":"Adversarial Robustness in Machine Learning","score":0.9128999710083008,"subfield":{"id":"https://openalex.org/subfields/1702","display_name":"Artificial Intelligence"},"field":{"id":"https://openalex.org/fields/17","display_name":"Computer Science"},"domain":{"id":"https://openalex.org/domains/3","display_name":"Physical Sciences"}},"topics":[{"id":"https://openalex.org/T11689","display_name":"Adversarial Robustness in Machine Learning","score":0.9128999710083008,"subfield":{"id":"https://openalex.org/subfields/1702","display_name":"Artificial Intelligence"},"field":{"id":"https://openalex.org/fields/17","display_name":"Computer Science"},"domain":{"id":"https://openalex.org/domains/3","display_name":"Physical Sciences"}},{"id":"https://openalex.org/T10775","display_name":"Generative Adversarial Networks and Image Synthesis","score":0.027699999511241913,"subfield":{"id":"https://openalex.org/subfields/1707","display_name":"Computer Vision and Pattern Recognition"},"field":{"id":"https://openalex.org/fields/17","display_name":"Computer Science"},"domain":{"id":"https://openalex.org/domains/3","display_name":"Physical Sciences"}},{"id":"https://openalex.org/T10388","display_name":"Advanced Steganography and Watermarking Techniques","score":0.012500000186264515,"subfield":{"id":"https://openalex.org/subfields/1707","display_name":"Computer Vision and Pattern Recognition"},"field":{"id":"https://openalex.org/fields/17","display_name":"Computer Science"},"domain":{"id":"https://openalex.org/domains/3","display_name":"Physical Sciences"}}],"keywords":[{"id":"https://openalex.org/keywords/watermark","display_name":"Watermark","score":0.9114000201225281},{"id":"https://openalex.org/keywords/digital-watermarking","display_name":"Digital watermarking","score":0.8543000221252441},{"id":"https://openalex.org/keywords/robustness","display_name":"Robustness (evolution)","score":0.6394000053405762},{"id":"https://openalex.org/keywords/embedding","display_name":"Embedding","score":0.5454999804496765},{"id":"https://openalex.org/keywords/image","display_name":"Image (mathematics)","score":0.4934999942779541},{"id":"https://openalex.org/keywords/decoding-methods","display_name":"Decoding methods","score":0.4684000015258789},{"id":"https://openalex.org/keywords/image-quality","display_name":"Image quality","score":0.438400000333786},{"id":"https://openalex.org/keywords/encoder","display_name":"Encoder","score":0.43320000171661377},{"id":"https://openalex.org/keywords/artificial-neural-network","display_name":"Artificial neural network","score":0.37700000405311584}],"concepts":[{"id":"https://openalex.org/C164112704","wikidata":"https://www.wikidata.org/wiki/Q7974348","display_name":"Watermark","level":3,"score":0.9114000201225281},{"id":"https://openalex.org/C150817343","wikidata":"https://www.wikidata.org/wiki/Q875932","display_name":"Digital watermarking","level":3,"score":0.8543000221252441},{"id":"https://openalex.org/C41008148","wikidata":"https://www.wikidata.org/wiki/Q21198","display_name":"Computer science","level":0,"score":0.8482000231742859},{"id":"https://openalex.org/C63479239","wikidata":"https://www.wikidata.org/wiki/Q7353546","display_name":"Robustness (evolution)","level":3,"score":0.6394000053405762},{"id":"https://openalex.org/C41608201","wikidata":"https://www.wikidata.org/wiki/Q980509","display_name":"Embedding","level":2,"score":0.5454999804496765},{"id":"https://openalex.org/C154945302","wikidata":"https://www.wikidata.org/wiki/Q11660","display_name":"Artificial intelligence","level":1,"score":0.5307999849319458},{"id":"https://openalex.org/C115961682","wikidata":"https://www.wikidata.org/wiki/Q860623","display_name":"Image (mathematics)","level":2,"score":0.4934999942779541},{"id":"https://openalex.org/C57273362","wikidata":"https://www.wikidata.org/wiki/Q576722","display_name":"Decoding methods","level":2,"score":0.4684000015258789},{"id":"https://openalex.org/C55020928","wikidata":"https://www.wikidata.org/wiki/Q3813865","display_name":"Image quality","level":3,"score":0.438400000333786},{"id":"https://openalex.org/C118505674","wikidata":"https://www.wikidata.org/wiki/Q42586063","display_name":"Encoder","level":2,"score":0.43320000171661377},{"id":"https://openalex.org/C31972630","wikidata":"https://www.wikidata.org/wiki/Q844240","display_name":"Computer vision","level":1,"score":0.4138000011444092},{"id":"https://openalex.org/C50644808","wikidata":"https://www.wikidata.org/wiki/Q192776","display_name":"Artificial neural network","level":2,"score":0.37700000405311584},{"id":"https://openalex.org/C189950617","wikidata":"https://www.wikidata.org/wiki/Q937228","display_name":"Property (philosophy)","level":2,"score":0.3677999973297119},{"id":"https://openalex.org/C153258448","wikidata":"https://www.wikidata.org/wiki/Q1199743","display_name":"Gradient descent","level":3,"score":0.3379000127315521},{"id":"https://openalex.org/C2221639","wikidata":"https://www.wikidata.org/wiki/Q2877","display_name":"Discrete cosine transform","level":3,"score":0.3330000042915344},{"id":"https://openalex.org/C2988773926","wikidata":"https://www.wikidata.org/wiki/Q25104379","display_name":"Generative adversarial network","level":3,"score":0.31940001249313354},{"id":"https://openalex.org/C2777210771","wikidata":"https://www.wikidata.org/wiki/Q4927124","display_name":"Block (permutation group theory)","level":2,"score":0.31459999084472656},{"id":"https://openalex.org/C2777303404","wikidata":"https://www.wikidata.org/wiki/Q759757","display_name":"Convergence (economics)","level":2,"score":0.31220000982284546},{"id":"https://openalex.org/C79403827","wikidata":"https://www.wikidata.org/wiki/Q3988","display_name":"Real-time computing","level":1,"score":0.28060001134872437},{"id":"https://openalex.org/C57869625","wikidata":"https://www.wikidata.org/wiki/Q1783502","display_name":"Rate of convergence","level":3,"score":0.2782999873161316},{"id":"https://openalex.org/C190502265","wikidata":"https://www.wikidata.org/wiki/Q17069496","display_name":"MNIST database","level":3,"score":0.27390000224113464},{"id":"https://openalex.org/C153180895","wikidata":"https://www.wikidata.org/wiki/Q7148389","display_name":"Pattern recognition (psychology)","level":2,"score":0.26829999685287476},{"id":"https://openalex.org/C108583219","wikidata":"https://www.wikidata.org/wiki/Q197536","display_name":"Deep learning","level":2,"score":0.2574000060558319},{"id":"https://openalex.org/C106430172","wikidata":"https://www.wikidata.org/wiki/Q6002272","display_name":"Image restoration","level":4,"score":0.2540000081062317},{"id":"https://openalex.org/C2780581891","wikidata":"https://www.wikidata.org/wiki/Q15738686","display_name":"Copy protection","level":4,"score":0.2531999945640564},{"id":"https://openalex.org/C124101348","wikidata":"https://www.wikidata.org/wiki/Q172491","display_name":"Data mining","level":1,"score":0.25209999084472656},{"id":"https://openalex.org/C155032097","wikidata":"https://www.wikidata.org/wiki/Q798503","display_name":"Backpropagation","level":3,"score":0.25060001015663147}],"mesh":[],"locations_count":2,"locations":[{"id":"doi:10.1109/tdsc.2025.3650683","is_oa":false,"landing_page_url":"https://doi.org/10.1109/tdsc.2025.3650683","pdf_url":null,"source":{"id":"https://openalex.org/S133795288","display_name":"IEEE Transactions on Dependable and Secure Computing","issn_l":"1545-5971","issn":["1545-5971","1941-0018","2160-9209"],"is_oa":false,"is_in_doaj":false,"is_core":true,"host_organization":"https://openalex.org/P4310320439","host_organization_name":"IEEE Computer Society","host_organization_lineage":["https://openalex.org/P4310320439","https://openalex.org/P4310319808"],"host_organization_lineage_names":["IEEE Computer Society","Institute of Electrical and Electronics Engineers"],"type":"journal"},"license":null,"license_id":null,"version":"publishedVersion","is_accepted":true,"is_published":true,"raw_source_name":"IEEE Transactions on Dependable and Secure Computing","raw_type":"journal-article"},{"id":"pmh:oai:pure.atira.dk:publications/70aed4c8-0cbc-449a-999c-8985268a4300","is_oa":true,"landing_page_url":"https://hdl.handle.net/2031/70aed4c8-0cbc-449a-999c-8985268a4300","pdf_url":null,"source":{"id":"https://openalex.org/S7407055387","display_name":"CityU Scholars","issn_l":null,"issn":null,"is_oa":false,"is_in_doaj":false,"is_core":false,"host_organization":null,"host_organization_name":null,"host_organization_lineage":[],"host_organization_lineage_names":[],"type":"repository"},"license":"other-oa","license_id":"https://openalex.org/licenses/other-oa","version":"submittedVersion","is_accepted":false,"is_published":false,"raw_source_name":"An, H, Hua, G, Du, W, Cao, H, Tao, Y, Xu, G, Rahardja, S & Fang, Y 2026, 'Decoder Gradient Shields : A Family of Provable and High-Fidelity Methods Against Gradient-Based Box-Free Watermark Removal', IEEE Transactions on Dependable and Secure Computing, vol. 23, no. 3, pp. 5015-5028. https://doi.org/10.1109/TDSC.2025.3650683","raw_type":"info:eu-repo/semantics/publishedVersion"}],"best_oa_location":{"id":"pmh:oai:pure.atira.dk:publications/70aed4c8-0cbc-449a-999c-8985268a4300","is_oa":true,"landing_page_url":"https://hdl.handle.net/2031/70aed4c8-0cbc-449a-999c-8985268a4300","pdf_url":null,"source":{"id":"https://openalex.org/S7407055387","display_name":"CityU Scholars","issn_l":null,"issn":null,"is_oa":false,"is_in_doaj":false,"is_core":false,"host_organization":null,"host_organization_name":null,"host_organization_lineage":[],"host_organization_lineage_names":[],"type":"repository"},"license":"other-oa","license_id":"https://openalex.org/licenses/other-oa","version":"submittedVersion","is_accepted":false,"is_published":false,"raw_source_name":"An, H, Hua, G, Du, W, Cao, H, Tao, Y, Xu, G, Rahardja, S & Fang, Y 2026, 'Decoder Gradient Shields : A Family of Provable and High-Fidelity Methods Against Gradient-Based Box-Free Watermark Removal', IEEE Transactions on Dependable and Secure Computing, vol. 23, no. 3, pp. 5015-5028. https://doi.org/10.1109/TDSC.2025.3650683","raw_type":"info:eu-repo/semantics/publishedVersion"},"sustainable_development_goals":[],"awards":[{"id":"https://openalex.org/G5362313529","display_name":null,"funder_award_id":"R-MA123-R205-0008","funder_id":"https://openalex.org/F4320320751","funder_display_name":"Ministry of Education - Singapore"},{"id":"https://openalex.org/G7486496408","display_name":null,"funder_award_id":"62502075","funder_id":"https://openalex.org/F4320321001","funder_display_name":"National Natural Science Foundation of China"}],"funders":[{"id":"https://openalex.org/F4320320751","display_name":"Ministry of Education - Singapore","ror":"https://ror.org/01kcva023"},{"id":"https://openalex.org/F4320321001","display_name":"National Natural Science Foundation of China","ror":"https://ror.org/01h0zpd94"}],"has_content":{"grobid_xml":false,"pdf":false},"content_urls":null,"referenced_works_count":0,"referenced_works":[],"related_works":[],"abstract_inverted_index":{"Box-free":[0],"model":[1],"watermarking":[2,213],"has":[3,51],"gained":[4],"significant":[5],"attention":[6],"in":[7,34,127,196],"deep":[8],"neural":[9],"network":[10],"(DNN)":[11],"intellectual":[12],"property":[13],"protection":[14],"due":[15],"to":[16,23,60,71,92,96,175],"its":[17,21],"model-agnostic":[18],"nature":[19],"and":[20,46,126,140,152,205],"ability":[22],"flexibly":[24],"manage":[25],"high-entropy":[26],"image":[27,182,206],"outputs":[28],"from":[29,157,171],"generative":[30],"models.":[31],"Typically":[32],"operating":[33],"a":[35,98,111,135,219],"black-box":[36],"manner,":[37],"it":[38],"employs":[39],"an":[40],"encoder-decoder":[41],"framework":[42],"for":[43,57,138,143],"watermark":[44,99,158,169],"embedding":[45],"extraction.":[47],"While":[48],"existing":[49],"research":[50],"focused":[52],"primarily":[53],"on":[54,203],"the":[55,58,64,74,85,119,123,128,132,147,155,163,168,176,185,190,210],"encoders":[56],"robustness":[59],"resist":[61],"various":[62],"attacks,":[63],"decoders":[65],"have":[66],"been":[67],"largely":[68],"overlooked,":[69],"leading":[70],"attacks":[72],"against":[73,84],"watermark.":[75],"In":[76],"this":[77,103],"paper,":[78],"we":[79,105],"identify":[80],"one":[81],"such":[82],"attack":[83],"decoder,":[86,133],"where":[87],"query":[88],"responses":[89],"are":[90],"utilized":[91],"obtain":[93],"backpropagated":[94],"gradients":[95,156],"train":[97],"remover.":[100],"To":[101],"address":[102],"issue,":[104],"propose":[106],"Decoder":[107],"Gradient":[108],"Shields":[109],"(DGSs),":[110],"family":[112],"of":[113,131,150,154,184,192,223],"defense":[114,220],"mechanisms,":[115],"including":[116],"DGS":[117],"at":[118,122],"output":[120],"(DGS-O),":[121],"input":[124],"(DGS-I),":[125],"layers":[129],"(DGS-L)":[130],"with":[134,209],"closed-form":[136],"solution":[137],"DGS-O":[139],"provable":[141],"performance":[142],"all":[144,226],"DGS.":[145],"Leveraging":[146],"joint":[148],"design":[149],"reorienting":[151],"rescaling":[153],"channel":[159],"gradient":[160],"leaking":[161],"queries,":[162],"proposed":[164,194],"DGSs":[165,195,217],"effectively":[166],"prevent":[167],"remover":[170],"achieving":[172],"training":[173],"convergence":[174],"desired":[177],"low-loss":[178],"value,":[179],"while":[180],"preserving":[181],"quality":[183],"decoder":[186],"output.":[187],"We":[188],"demonstrate":[189],"effectiveness":[191],"our":[193,216],"diverse":[197],"application":[198],"scenarios.":[199],"Our":[200],"experimental":[201],"results":[202],"deraining":[204],"generation":[207],"tasks":[208],"state-of-the-art":[211],"box-free":[212],"show":[214],"that":[215],"achieve":[218],"success":[221],"rate":[222],"100%":[224],"under":[225],"settings.":[227]},"counts_by_year":[],"updated_date":"2026-06-11T09:08:48.828518","created_date":"2026-01-05T00:00:00"}
